logo

Qakbot Malware: Exploring Its Diverse Distribution Methods

ID: 3efa7160-2bec-55da-93b1-6fad306d0cbc

STIX ID: report--3efa7160-2bec-55da-93b1-6fad306d0cbc

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-11-26

Date Updated: 2026-07-16

...
...

This report analyzes active Qakbot campaigns that deliver a modular banking trojan via malspam using OneNote attachments and archived script files (.wsf, .jse, .hta), describing multi-stage chains (BAT/PowerShell/WScript/msthta → DLL payload executed with rundll32), process injection and credential-theft capabilities, and providing IoCs (file hashes and download URLs), MITRE ATT&CK mappings, process diagrams, and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.